This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Log for checking

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have been having a problem with casalemedia, and i am not sure if i got rid of it for good.
Logs are posted below, please let me know if you see anything suspicious.

Logfile of HijackThis v1.99.1
Scan saved at 11:54:10 PM, on 1/08/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\PROGRA~1\CACHEM~1\CachemanXP.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\BOINC\boincmgr.exe
C:\Program Files\BOINC\boinc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Grisoft\AVG Free\avgwb.dat
C:\Program Files\Security & Anti Spyware\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Security & Anti Spyware\Spybot - Search & Destroy\SpybotSD.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: BOINC Manager.lnk = C:\Program Files\BOINC\boincmgr.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1152118728789
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: CachemanXP (CachemanXPService) - OuterTechnologies - C:\PROGRA~1\CACHEM~1\CachemanXP.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe



———————————————————
ewido anti-spyware - Scan Report
———————————————————

+ Created at: 12:42:25 AM 2/08/2006

+ Scan result:



:mozilla.236:C:\Documents and Settings\Veronica\Application Data\Mozilla\Firefox\Profiles\ovwr0epl.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Veronica\Cookies\veronica@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
:mozilla.178:C:\Documents and Settings\Veronica\Application Data\Mozilla\Firefox\Profiles\ovwr0epl.default\cookies.txt -> TrackingCookie.Burstnet : No action taken.
:mozilla.179:C:\Documents and Settings\Veronica\Application Data\Mozilla\Firefox\Profiles\ovwr0epl.default\cookies.txt -> TrackingCookie.Burstnet : No action taken.
:mozilla.168:C:\Documents and Settings\Veronica\Application Data\Mozilla\Firefox\Profiles\ovwr0epl.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.169:C:\Documents and Settings\Veronica\Application Data\Mozilla\Firefox\Profiles\ovwr0epl.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.170:C:\Documents and Settings\Veronica\Application Data\Mozilla\Firefox\Profiles\ovwr0epl.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.27:C:\Documents and Settings\Veronica\Application Data\Mozilla\Firefox\Profiles\ovwr0epl.default\cookies.txt -> TrackingCookie.Com : No action taken.
:mozilla.259:C:\Documents and Settings\Veronica\Application Data\Mozilla\Firefox\Profiles\ovwr0epl.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
:mozilla.260:C:\Documents and Settings\Veronica\Application Data\Mozilla\Firefox\Profiles\ovwr0epl.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
:mozilla.224:C:\Documents and Settings\Veronica\Application Data\Mozilla\Firefox\Profiles\ovwr0epl.default\cookies.txt -> TrackingCookie.Hotlog : No action taken.
:mozilla.107:C:\Documents and Settings\Veronica\Application Data\Mozilla\Firefox\Profiles\ovwr0epl.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.108:C:\Documents and Settings\Veronica\Application Data\Mozilla\Firefox\Profiles\ovwr0epl.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.109:C:\Documents and Settings\Veronica\Application Data\Mozilla\Firefox\Profiles\ovwr0epl.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.110:C:\Documents and Settings\Veronica\Application Data\Mozilla\Firefox\Profiles\ovwr0epl.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.243:C:\Documents and Settings\Veronica\Application Data\Mozilla\Firefox\Profiles\ovwr0epl.default\cookies.txt -> TrackingCookie.Spylog : No action taken.
:mozilla.39:C:\Documents and Settings\Veronica\Application Data\Mozilla\Firefox\Profiles\ovwr0epl.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.40:C:\Documents and Settings\Veronica\Application Data\Mozilla\Firefox\Profiles\ovwr0epl.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.176:C:\Documents and Settings\Veronica\Application Data\Mozilla\Firefox\Profiles\ovwr0epl.default\cookies.txt -> TrackingCookie.Tacoda : No action taken.
:mozilla.177:C:\Documents and Settings\Veronica\Application Data\Mozilla\Firefox\Profiles\ovwr0epl.default\cookies.txt -> TrackingCookie.Tacoda : No action taken.
C:\Documents and Settings\Veronica\Cookies\veronica@tacoda[1].txt -> TrackingCookie.Tacoda : No action taken.
:mozilla.152:C:\Documents and Settings\Veronica\Application Data\Mozilla\Firefox\Profiles\ovwr0epl.default\cookies.txt -> TrackingCookie.Yadro : No action taken.
:mozilla.73:C:\Documents and Settings\Veronica\Application Data\Mozilla\Firefox\Profiles\ovwr0epl.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.74:C:\Documents and Settings\Veronica\Application Data\Mozilla\Firefox\Profiles\ovwr0epl.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.75:C:\Documents and Settings\Veronica\Application Data\Mozilla\Firefox\Profiles\ovwr0epl.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.76:C:\Documents and Settings\Veronica\Application Data\Mozilla\Firefox\Profiles\ovwr0epl.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.78:C:\Documents and Settings\Veronica\Application Data\Mozilla\Firefox\Profiles\ovwr0epl.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.77:C:\Documents and Settings\Veronica\Application Data\Mozilla\Firefox\Profiles\ovwr0epl.default\cookies.txt -> TrackingCookie.Zedo : No action taken.
:mozilla.79:C:\Documents and Settings\Veronica\Application Data\Mozilla\Firefox\Profiles\ovwr0epl.default\cookies.txt -> TrackingCookie.Zedo : No action taken.
:mozilla.82:C:\Documents and Settings\Veronica\Application Data\Mozilla\Firefox\Profiles\ovwr0epl.default\cookies.txt -> TrackingCookie.Zedo : No action taken.
:mozilla.83:C:\Documents and Settings\Veronica\Application Data\Mozilla\Firefox\Profiles\ovwr0epl.default\cookies.txt -> TrackingCookie.Zedo : No action taken.
:mozilla.84:C:\Documents and Settings\Veronica\Application Data\Mozilla\Firefox\Profiles\ovwr0epl.default\cookies.txt -> TrackingCookie.Zedo : No action taken.
:mozilla.85:C:\Documents and Settings\Veronica\Application Data\Mozilla\Firefox\Profiles\ovwr0epl.default\cookies.txt -> TrackingCookie.Zedo : No action taken.
:mozilla.86:C:\Documents and Settings\Veronica\Application Data\Mozilla\Firefox\Profiles\ovwr0epl.default\cookies.txt -> TrackingCookie.Zedo : No action taken.


::Report end





Thanks a lot,

Ver
Hi rica:
What sort of problem are you having with casalemedia ? I see no mention of it in your Hijack This logfile and only a tracking cookie by that name, in the Ewido scan.

Please print, or copy and paste this text into a Notepad file and place it on your desktop, to review as you work. Please proceed with this fix in the order provided below.

* Clean your Cache and Cookies in Firefox:
Go to Tools > Options.
Click Privacy in the menu on the left side of the Options window.
Click the Clear button located to the right of each option (History, Cookies, Cache).
Click OK to close the Options window
Alternatively, you can clear all information stored while browsing by clicking Clear All.
A confirmation dialog box will be shown before clearing the information.

* Clean other Temporary files + Recycle bin

Go to start > run and type: cleanmgr and click ok.
Let it scan your system for files to remove.
Make sure Temporary Files, Temporary Internet Files, and Recycle Bin are the only things checked.
Press OK to remove them.


Close all windows and browsers, leaving only HijackThis running.

Place a check beside each of these entries listed below, if still present.

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

Click on Fix Checked when finished and exit HijackThis.


Please run Hijack This again. Scan and copy the log, then post it into this topic.

Please advise if any problems remain.

Please use the [external image: Posted Image] button to reply.
Logfile of HijackThis v1.99.1
Scan saved at 10:09:11 PM, on 6/08/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\PROGRA~1\CACHEM~1\CachemanXP.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Security & Anti Spyware\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: BOINC Manager.lnk = C:\Program Files\BOINC\boincmgr.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1152118728789
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: CachemanXP (CachemanXPService) - OuterTechnologies - C:\PROGRA~1\CACHEM~1\CachemanXP.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe



How am i looking now?

Thanks,

Rica.
Hi rica:
Your log looked fine previously and it still looks clean.
Since you already have Ewido, why not update it and let it remove anything it finds.

Your Hijack This logfile looks to be clean.
If there are no problems, please be sure to use the link to see TonyKlein's good advice (below). Those Protection programs offered free, are some of the best available.

One of the best features of Windows XP is the System Restore option, however if Malware infects a computer with this operating system the Malware can be backed up in the System Restore folder. Therefore, clearing the restore points is necessary after a virus removal.

To reset your restore points, please note that you will need to log into your computer with an account which has full administrator access. You will know if the account has administrator access because you will be able to see the System Restore tab. If the tab is missing, you are logged in under a limited account.

(winXP)

1. Turn off System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

2. Reboot.

3. Turn ON System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UN-Check *Turn off System Restore*.
Click Apply, and then click OK.

* Clean your Cache and Cookies in IE:
Close all instances of Outlook Express and Internet Explorer
Go to Control Panel > Internet Options > General tab
Click the "Delete Cookies" button
Next to it, Click the "Delete Files" button
When prompted, place a check in: "Delete all offline content", click OK

* Clean your Cache and Cookies in Firefox (In case you also have Firefox installed):
Go to Tools > Options.
Click Privacy in the menu on the left side of the Options window.
Click the Clear button located to the right of each option (History, Cookies, Cache).
Click OK to close the Options window
Alternatively, you can clear all information stored while browsing by clicking Clear All.
A confirmation dialog box will be shown before clearing the information.

* Clean other Temporary files + Recycle bin

Go to start > run and type: cleanmgr and click ok.
Let it scan your system for files to remove.
Make sure Temporary Files, Temporary Internet Files, and Recycle Bin are the only things checked.
Press OK to remove them.

Also, see TonyKlein's good advice and highly recommended FREE PROTECTION PROGRAMS. A must for all PC users.
http://forums.spywareinfo.com/index.php?showtopic=60955
So how did I get infected in the first place?

Safe surfing. :wavey:
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI